EU AI Act and ISO 42001 for Israeli companies: a 2026 guide
The short answer: yes, the EU AI Act can apply to an Israeli company with no office in Europe. It reaches any provider that sells an AI system into the EU market, and any provider or deployer anywhere whose system produces output that is used in the EU. The heavy obligations apply only to a short list of high-risk uses, and the deadline for those moved in July 2026 to 2 December 2027. ISO/IEC 42001 is a voluntary management standard, and an Israeli SMB usually needs it only when a customer asks for it in procurement.
Last updated: September 9, 2026
Checked on 9 September 2026 against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), the European Commission's AI Act pages, ISO's page for ISO/IEC 42001:2023, and the Israeli sources linked at the end. This is orientation for a company owner or operations lead, and it is not legal advice. Dates and thresholds are exactly the things that change, so check the current text before you rely on one.
Does the EU AI Act apply to an Israeli company?
Yes, if your AI system reaches the EU in one of the ways listed in Article 2. The Regulation does not care where the company is registered. It cares where the system is placed on the market and where its output is used.
Article 2(1) covers providers placing an AI system or a general-purpose AI model on the EU market "irrespective of whether those providers are established or located within the Union or in a third country"; providers and deployers in a third country "where the output produced by the AI system is used in the Union"; and importers and distributors. Under Article 25, putting your name on someone else's high-risk system, or substantially modifying it, makes you its provider.
Two definitions carry the whole Regulation. A provider builds a system (or has it built) and puts it out under its own name. A deployer uses a system under its own authority in a business setting. An Israeli company is often both: provider of the SaaS it sells, deployer of the tools it runs internally.
The "output used in the Union" clause is the one that surprises people. Recital 22 explains the intent: to stop an EU company from sending data to a third-country operator, running the AI there, and importing the result untouched by the rules. So an Israeli SaaS with EU customers is covered as a provider. An Israeli exporter scoring EU distributors with an internal model is covered as a deployer, though for most such uses the obligations are light or none. A marketing team in Tel Aviv generating campaign content for EU audiences meets Article 50 only when it publishes deepfakes or AI-written text on matters of public interest.
A team that uses AI only for Israeli operations, with no EU customer and no output crossing into the EU, is outside the Regulation. Israeli privacy law still applies, and that is covered further down.
What does the AI Act actually require, by risk tier?
It bans a short list of practices, regulates a longer list of high-risk uses heavily, imposes disclosure duties on a few interaction types, and leaves everything else alone. Most business automation lands in the last bucket.
| Tier | What is in it | What you have to do |
|---|---|---|
| Prohibited (Article 5) | Harmful manipulation, exploiting age, disability or economic situation, social scoring, crime prediction from profiling alone, untargeted scraping of faces, emotion recognition at work or in schools, biometric categorisation by protected traits, real-time remote biometric ID in public spaces. Since the 2026 amendment: non-consensual intimate imagery and child sexual abuse material. | Do not build or use them. In force since 2 February 2025; the two new prohibitions from 2 December 2026. |
| High-risk (Annex III and Annex I) | Annex III: biometrics, critical infrastructure, education, employment (CV screening, candidate ranking, promotion and termination, task allocation, performance monitoring), essential services (credit scoring, life and health insurance pricing, public benefits), law enforcement, migration, justice and elections. Annex I: AI as a safety component of a product already under EU product law. | Providers: risk management, data governance, technical file, logging, instructions for use, human oversight design, testing, conformity assessment, CE marking, registration. Deployers (Article 26): use per instructions, competent human oversight, logs kept at least 6 months, tell workers and affected people. Annex III from 2 December 2027, Annex I from 2 August 2028. |
| Limited risk (Article 50) | Chatbots and anything that talks to a person, generators of synthetic audio, image, video or text, deepfakes. | Tell people they are dealing with an AI unless it is obvious. Mark synthetic output in a machine-readable way. Label deepfakes. From 2 August 2026; systems already on the market have until 2 December 2026 for the marking duty. |
| Minimal risk | Everything else: invoice extraction, ticket routing, CRM enrichment, internal search, summarisation, forecasting. | Nothing under the AI Act. |
Two details decide most classification questions.
First, Article 6(3) lets an Annex III system out of the high-risk tier when it does a narrow procedural task, improves the result of a completed human activity, detects deviations from a pattern without replacing human judgement, or does preparatory work. An agent that pre-fills a candidate's details into the ATS is preparatory. An agent that ranks the candidates is high-risk. And any system that profiles natural persons is always high-risk, whatever the derogation says.
Second, the employment and credit categories catch ordinary businesses. Sell an HR screening tool into Germany, or score EU consumers from a Tel Aviv fintech, and you are a high-risk provider with the full documentation burden, whatever your size.
What are the general-purpose AI obligations when you build on Claude, GPT or Gemini?
The GPAI obligations sit on the model provider, so on Anthropic, OpenAI and Google, and they do not transfer to you when you call the API. Your obligations come from what your system does, under the tiers above.
Article 53 requires model providers to keep technical documentation, give downstream builders enough information to understand the model's capabilities and limits, run a copyright policy, and publish a summary of training content. These have applied since 2 August 2025. The General-Purpose AI Code of Practice was published on 10 July 2025, and Anthropic, OpenAI, Google, Microsoft and Amazon are among its signatories.
The question I get asked most: does fine-tuning make us a model provider? Almost never. The Commission's guidelines set an indicative threshold of more than one third of the original model's training compute. Fine-tuning a frontier model on your support tickets comes nowhere near that.
What you do inherit is the downstream side of Article 53: you are entitled to the provider's documentation and you are expected to use it. When we scope an AI agent, the vendor's usage policy and system card become an input to the design, and the vendor contract goes into the compliance file.
When does each part of the Act apply?
The Act entered into force on 1 August 2024, and most obligations were due on 2 August 2026, until the Digital Omnibus on AI moved the high-risk dates. That amendment is Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July 2026, six days before the original high-risk deadline. The Commission's AI Act page shows the amended dates.
| Date | What applies | Status on 9 September 2026 |
|---|---|---|
| 1 August 2024 | Regulation (EU) 2024/1689 enters into force | Done |
| 2 February 2025 | Prohibited practices (Article 5) | In force |
| 2 August 2025 | GPAI model obligations, governance, penalties | In force |
| 2 August 2026 | Article 50 transparency duties and most remaining provisions | In force |
| 2 December 2026 | Marking of synthetic content for systems on the market before 2 August 2026; the two new prohibitions | Coming |
| 2 December 2027 | High-risk obligations for Annex III systems (was 2 August 2026) | Moved by the omnibus |
| 2 August 2028 | High-risk obligations for Annex I product-embedded systems (was 2 August 2027) | Moved by the omnibus |
The omnibus also softened Article 4 on AI literacy from a duty to "ensure" staff competence to a duty to "support" it, and extended the SME simplifications to small mid-caps. It left the GPAI obligations alone.
One caution. The work for a high-risk provider (technical file, risk management system, conformity assessment) takes most of a year for a small team. If your product is in Annex III, December 2027 is closer than it looks.
What are the penalties?
The figures are in Article 99. A prohibited practice: up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher. Most other breaches, including high-risk and transparency duties: up to EUR 15 million or 3%. Incorrect or misleading information to authorities: up to EUR 7.5 million or 1%.
For SMEs and start-ups the rule flips: each fine is capped at whichever of the two figures is lower. Article 101 lets the Commission fine GPAI model providers up to 3% or EUR 15 million, which again lands on the model companies.
Enforcement against a third-country company runs through the market surveillance authority of the member state where the system is used, and a high-risk provider outside the EU must appoint an authorised representative inside it (Article 22). I could find no published fine against an Israeli company under the Act, and the high-risk regime is not yet in application, so the case law is empty for now.
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is the international standard for an AI management system, an AIMS. ISO published it in December 2023. It tells an organisation how to govern the AI it builds or uses, and it is built on the same harmonised structure as ISO 27001, so a company that already runs an information security management system will recognise every clause.
Clauses 4 to 10 are the mandatory system: context and scope, leadership and an AI policy, planning (risk assessment, AI impact assessment, objectives), support, operation, performance evaluation and improvement. Annex A lists 38 reference controls in 9 groups: AI policy, internal roles, resources, impact assessment, the system lifecycle, data, information for interested parties, responsible use, and third-party relationships. Annex B is implementation guidance, Annex C lists objectives and risk sources, Annex D covers fitting the AIMS beside other management systems.
In plain terms, a certified organisation can show an auditor a signed AI policy, an inventory of AI systems with an owner for each, a risk and impact assessment per system that covers the people affected as well as the company, lifecycle controls from requirements to retirement, data governance, supplier controls for model vendors and integrators, and a monitoring and review loop.
Certification comes from accredited certification bodies, the same kind that audit 27001, on the usual 3-year cycle with annual surveillance. Several large model and cloud vendors already hold it. Microsoft publishes its certificates, and notes that a customer still has to have its own implementation assessed separately.
How does ISO 42001 map to the AI Act?
Closely on the management layer, and not at all on the product layer. The standard says how to run governance; the Act says which systems need which controls and what the technical file must contain.
| AI Act obligation | Where 42001 covers it | Gap |
|---|---|---|
| Risk management system (Article 9) | Clause 6 risk assessment, A.5 impact assessment | The Act wants risks to health, safety and fundamental rights specifically |
| Data governance (Article 10) | A.7 data for AI systems | The Act's bias examination is more specific |
| Technical documentation (Article 11) | A.6 lifecycle documentation | Annex IV of the Act prescribes the content |
| Logging (Articles 12 and 26) | A.6.2.8 event logging | The Act sets the minimum retention |
| Transparency (Articles 13 and 50) | A.8 information for interested parties | 42001 has no machine-readable marking duty |
| Human oversight (Article 14) | A.9 responsible use | 42001 leaves the oversight design to you |
| Value-chain duties (Article 25) | A.10 third-party relationships | Good fit |
| Post-market monitoring (Article 72) | Clause 9, A.6.2.6 operation and monitoring | Good fit |
| Conformity assessment, CE marking, registration | Nothing | Product-law mechanics with no management-standard equivalent |
So 42001 is the scaffolding an Annex III provider would build on, and it gets a minimal-risk company most of the way to "we govern our AI properly", with a certificate to prove it. The EU has not adopted it as a harmonised standard under the Act, so certification carries no presumption of conformity.
Does an Israeli SMB need ISO 42001?
Usually no, until a customer asks for it, and then yes.
Nothing in Israeli law and nothing in the AI Act requires the certificate. The pressure comes from procurement. Enterprise security questionnaires now carry an AI section, EU customers ask suppliers to show AI governance, and a 42001 certificate answers 30 questions in one line. If you sell software or AI-heavy services to enterprises or into Europe, the deal that stalls on that question is the moment the certificate pays for itself.
If you are a 40-person company using AI for internal operations with Israeli customers, the certificate buys you nothing that a written AI policy and a systems inventory would not. Do those anyway; they cost a week. A middle path we see often: implement the clauses, keep the evidence, skip the audit until the first customer requires the paper.
What does Israel itself require today?
Israel has no AI-specific statute as of September 2026. It regulates AI through a 2023 government policy, the Privacy Protection Law with its 2025 amendment, and sector regulators. That still leaves real obligations, spread across several documents.
The government's AI policy, published by the Ministry of Innovation, Science and Technology with the Ministry of Justice in December 2023, chose the opposite approach to Brussels: sectoral regulation over a horizontal law, risk-based, soft tools first. It lists 6 principles (human-centred AI, equality and non-discrimination, transparency and explainability, reliability and safety, accountability, innovation for social welfare) and set up a coordination centre for the sector regulators. The policy itself creates no penalties.
Amendment 13 to the Privacy Protection Law is the document with teeth. In force since 14 August 2025, it gave the Privacy Protection Authority administrative fines and orders to stop processing, widened the definitions of personal and highly sensitive data, required a privacy protection officer in many organisations, expanded notice duties at collection, and replaced database registration with notification for most companies. Any AI system that touches personal data of Israelis lives under this law.
The Authority published a draft guideline on applying the law to AI systems on 28 April 2025. The draft says the law applies from training to use, that information a system infers about a person is personal data, that processing for AI needs a legal basis and informed consent, that people must be told when they are dealing with a bot, that a privacy impact assessment is expected before deployment, that scraping personal data without consent is unlawful even from public profiles, and that an organisation needs a policy on staff use of generative tools. The Ministry of Finance and the tech industry pushed back hard in August 2025, and as of this guide's date every source we could reach still calls it a draft. Check the Authority's site for a final text, and treat the draft as a fair preview of how it will enforce. On automated decisions, Israeli law has no standalone right like GDPR Article 22; the draft reaches the same ground through notice, accuracy and access rights.
In finance, an inter-ministerial team (Israel Securities Authority, Ministry of Justice, Ministry of Finance, the Supervisor of Banks, the Capital Market Authority, the Competition Authority) published its final report on AI in the financial sector on 24 December 2025. It recommends a risk-based approach, puts responsibility for an AI system on the supervised financial entity whoever built the model, expects system-level explainability, and requires plain disclosure to customers when AI materially affects a service. These are recommendations to the regulators; the directives that follow are the ones to watch.
In health, the Ministry of Health has acted through information security so far. A March 2026 directive told healthcare organisations to stop using public external AI tools on organisational networks, and in June 2026 the Ministry blocked those tools in government hospitals. AI inside a medical device still goes through AMAR registration under the Medical Equipment Law.
A practical checklist for an Israeli company with EU customers or users
Written for the owner or ops lead, in the order we actually do it.
- Inventory every AI system, including the ChatGPT tabs: what it does, which model it calls, whose data goes in, whose decisions come out. ISO 42001 and the PPA draft both ask for this, so build it once.
- Classify each system against the tiers. Most will be minimal risk. Flag anything touching hiring, credit, insurance pricing, education or biometrics, and anything that profiles people.
- Map the data flows: which personal data enters each system, where it goes (the model vendor's region, your servers, an n8n instance), how long it stays.
- Write the disclosures: a line in the chat widget saying it is an AI, a label on generated images and videos that leave the company, a notice to candidates or customers when an AI shapes a decision about them.
- Design human oversight where it matters. Name the reviewer, give them authority to override, and log the override.
- Keep logs. Six months is the Act's floor for deployers of high-risk systems; we keep execution history for everything, because the first question after a wrong answer is "what did it see".
- Fix the supplier terms: data processing terms with the model vendor, no training on your data, a region you can name, the vendor's documentation on file. Same for any integrator, including us.
- Write the AI policy. Two pages: what the company uses AI for, what it will not do, who owns each system, how staff may use generative tools with company data, how incidents are reported.
- Bring counsel in for any Annex III classification call, any product sold into the EU that might be high-risk, the authorised representative question, and EU enterprise contracts with AI warranties.
- Revisit every 6 months. The dates in this guide moved once already.
This is orientation, not legal advice. Item 9 exists for a reason.
How does the way we build relate to these obligations?
Most of what the checklist asks for is already how a well-built automation looks, which is good news for anyone who has to retrofit it.
We build on n8n, Claude and Python, and each has a governance side. n8n keeps an execution log for every run, so "what did the system see and do" has an answer without extra tooling, and retention can be set to whatever the obligation is. A workflow on a canvas is also its own documentation: an auditor, or your own ops lead, can read the steps without reading code. Human oversight is a design choice we make early: approval nodes before anything that affects a person, a named reviewer, and the override recorded in the same log. That is what Article 14 asks a provider to design in and what Article 26 asks a deployer to staff. Our how we work page shows where those checkpoints sit in a project.
Ownership matters here more than people expect. On our projects the code, the workflows and the documentation transfer to the client. When a regulator or a customer asks who the provider is, the answer is you, and you hold the technical file, the logs and the right to change the system. A vendor who keeps the workflow on their own account has made you dependent on them for every audit question.
None of this makes a high-risk system compliant on its own; that takes the conformity assessment and a technical file built to Annex IV. It does mean that when we scope an AI consulting engagement, the inventory and the classification happen in the first week. The guide on implementing AI in a business walks the same sequence from the operational side, the organizational brain guide covers where the documentation lives once it exists, and the glossary has short definitions for the terms used here.
Frequently asked questions
We only use ChatGPT internally. Does the AI Act apply?
If none of the output is used in the EU and you sell nothing there, the AI Act does not apply to you. Israeli privacy law applies the moment personal data goes into the tool, and the Privacy Protection Authority's draft guideline expects an internal policy on staff use of generative tools. Write that policy, and check the vendor's terms on training with your data.
Is our chatbot a high-risk system?
Almost never. A customer-facing chatbot is a limited-risk system under Article 50, so it must tell people they are talking to an AI unless that is obvious. It becomes high-risk only if it does an Annex III job, such as deciding a credit application or screening a job candidate, and it is always high-risk if it profiles people.
Do we need an authorised representative in the EU?
Only providers of high-risk AI systems established outside the EU must appoint one, under Article 22, before making the system available there. Providers of general-purpose AI models outside the EU have the same duty under Article 54. A minimal-risk or limited-risk provider does not need one.
Does ISO 42001 certification make us compliant with the AI Act?
No. It shows you govern AI properly and covers most of the management-system obligations, but it is not a harmonised standard under the Act, so it gives no presumption of conformity, and it does nothing for the conformity assessment, CE marking and registration a high-risk product needs.
What changed in the July 2026 amendment?
Regulation (EU) 2026/1744 moved the Annex III high-risk deadline from 2 August 2026 to 2 December 2027 and the Annex I deadline from 2 August 2027 to 2 August 2028, gave systems already on the market until 2 December 2026 to mark synthetic content, added two prohibitions on intimate imagery and child abuse material, and softened the AI literacy duty. The prohibitions, GPAI obligations and Article 50 transparency duties kept their dates.
Where do we start if an EU customer sent us an AI governance questionnaire?
With the inventory and the data-flow map, because most of the questions are answered by those two documents. Then the AI policy, then the supplier terms with your model vendor. If the questionnaire asks for 42001, find out whether they want the certificate or evidence of the practices, because those are very different amounts of work.
Sources
Checked on 9 September 2026:
- Regulation (EU) 2024/1689 as amended, Articles 2, 4, 5, 6, 14, 22, 25, 26, 50, 53, 54, 99, 101, 113 and Annex III, read on artificialintelligenceact.eu, which mirrors the Official Journal text
- Regulation (EU) 2026/1744, the Digital Omnibus on AI, OJ 24 July 2026
- European Commission, AI Act page, GPAI Code of Practice and GPAI guidelines
- ISO/IEC 42001:2023 and Microsoft's ISO 42001 page
- Israel's AI policy, December 2023; Amendment 13 via law.co.il; the PPA draft AI guideline; the financial sector report; the Ministry of Health directive
Next step
If you have EU customers and no inventory yet, that is a 2-week piece of work, and every other obligation on this page starts from it. Talk to us and we will tell you which of your systems need a second look and which can be left alone.